redact-secret · Report
Unclassified assignment literal
Arbitrary literal in a sensitive-looking assignment, masked as project policy rather than a provider format.
Research record
2 events in the review history: 1 observed, 1 reviewed. Latest: observed on 2026-09-26 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
Shape not recorded.
Format facts
Provider documented ·
mutable-property-source· current · observed 2026-09-20Documentation for the one property varied in legacy twin fixtures (context-twin decision (#36)): no provider exists for an arbitrary literal. The recorded decision is that the twin keeps the value and mutates exactly one property of the assignment context; silence is project policy, never a format claim
- redact-secret/redact-secret-benchmarks @ main: docs/decisions/2026-09-20-extend-twins-to-assignment-context.mdprovider-documentation · last read 2026-09-20 · latest outcome read · supports no provider exists for an arbitrary literal. The recorded decision is that the twin keeps the value and mutates exactly one property of the assignment context; silence is project policy, never a format claim
Project policy ·
legacy-contract-tier· current · observed 2026-09-20The legacy contract records this grammar as project masking policy (tier T3), not as a provider format.
Source not recorded.
Project policy ·
dossier-research· current · observed 2026-09-26Legacy dossier research (verdict ready, tier T3) cited 2 sources; the dossier does not attribute sources to individual properties.
- redact-secret/redact-secret @ 8b6a5fde52ecb4dfce13f09c7a947062d21483c7: docs/audits/evidence/653/README.mdproject-research-note · last read 2026-09-26 · latest outcome read · supports Final research evidence recorded by the legacy dossier
- www.rfc-editor.org/rfc/rfc6749.txtstandard-or-rfc · last read 2026-10-03 · latest outcome read · supports Cited by the legacy dossier research for this family
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- none. An arbitrary literal (8 to 4096 bytes in core) assigned to a sensitive-looking name such as
client_secret; entropy only selects confidence. RFC 6749 allows any printable ASCII (VSCHAR), RFC 8265 any PRECIS freeform string. - Basis
- none possible; the family has no provider (
"provider": null). The #653 hunt found no source for the scored span; masking is project policy (T3, decision2026-09-26-qualify-bounded-t3-credential-policy, benchmarks#365, core #857), so the verdict isreadyat T3, consistent with the other three policy families. - Issuance
- not applicable.
- Contract in core
- detector-families.md; #653 record; the ADRs it cites cover the warn-on-high-signal-names policy.
In this benchmark
- Fixtures
- 237
- Left readable
- 35
- Redacted too much
- 0
- False alarms
- 1
237 fixtures: 3 expect a redaction, 122 must stay quiet, 112 record project policy. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T1Provider-documented | 9 | 1 | 0 | 0 |
| T3Project policy | 212 | 34 | 0 | 1 |
| T0Pending review | 16 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it | 237 | 114 | 0 | 1 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rules1 rule targets it | 237 | 62 | 0 | 0 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 237 | 35 | 0 | 1 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabledNo rule maps to it | 237 | 115 | 0 | 0 |
Looks like it, but isn't
- Collisions
- every provider family whose value sits in an assignment; a named provider detector wins.
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| gitleaks · rules 8.30.1 | generic-api-key | keyword-before-value assignment with a literal of 10 or more characters |
| openredaction · rules 1.1.5 | GENERIC_API_KEY | api key keyword + a value of 20 or more characters |
| openredaction · rules 1.1.5 | GENERIC_SECRET | password, passwd, pwd or secret keyword + a value of 8 or more characters |
| openredaction · rules 1.1.5 | OAUTH_CLIENT_SECRET | client secret or consumer secret keyword + 20 or more characters |
| openredaction · rules 1.1.5 | OAUTH_TOKEN | oauth token or access token keyword + 20 or more characters |
No rule maps to this family in flare-redact, trufflehog.
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
generic-literal-alphabet-edge-base64-standard-padded-in-envbase64-hex-representation-projections · credential-in-base64-or-hex-form | Project policyT3 · Project policy | Left readable |
generic-literal-alphabet-edge-base64-standard-padded-in-jsonbase64-hex-representation-projections · credential-in-base64-or-hex-form | Project policyT3 · Project policy | Left readable |
generic-literal-alphabet-edge-base64-standard-padded-in-urlbase64-hex-representation-projections · credential-in-base64-or-hex-form | Project policyT3 · Project policy | Left readable |
generic-literal-alphabet-edge-base64-standard-padded-three-layers-in-envbase64-hex-representation-projections · credential-in-nested-encoding-layers | Project policyT3 · Project policy | Left readable |
generic-literal-alphabet-edge-base64-standard-unpadded-in-envbase64-hex-representation-projections · credential-in-base64-or-hex-form | Project policyT3 · Project policy | Left readable |
generic-literal-alphabet-edge-base64-url-safe-padded-in-envbase64-hex-representation-projections · credential-in-base64-or-hex-form | Project policyT3 · Project policy | Left readable |
generic-literal-alphabet-edge-base64-url-safe-unpadded-in-envbase64-hex-representation-projections · credential-in-base64-or-hex-form | Project policyT3 · Project policy | Left readable |
generic-literal-alphabet-edge-base64-url-safe-unpadded-in-jsonbase64-hex-representation-projections · credential-in-base64-or-hex-form | Project policyT3 · Project policy | Left readable |
generic-literal-alphabet-edge-base64-url-safe-unpadded-in-urlbase64-hex-representation-projections · credential-in-base64-or-hex-form | Project policyT3 · Project policy | Left readable |
generic-literal-alphabet-edge-base64-url-safe-unpadded-of-base64-standard-padded-in-envbase64-hex-representation-projections · credential-in-nested-encoding-layers | Project policyT3 · Project policy | Left readable |
generic-literal-alphabet-edge-base64-url-safe-unpadded-of-hex-upper-of-base64-standard-padded-in-jsonbase64-hex-representation-projections · credential-in-nested-encoding-layers | Project policyT3 · Project policy | Left readable |
generic-literal-alphabet-edge-hex-lower-in-envbase64-hex-representation-projections · credential-in-base64-or-hex-form | Project policyT3 · Project policy | Left readable |
generic-literal-alphabet-edge-hex-lower-in-urlbase64-hex-representation-projections · credential-in-base64-or-hex-form | Project policyT3 · Project policy | Left readable |
generic-literal-alphabet-edge-hex-lower-of-base64-standard-padded-in-envbase64-hex-representation-projections · credential-in-nested-encoding-layers | Project policyT3 · Project policy | Left readable |
generic-literal-alphabet-edge-hex-lower-of-hex-lower-in-envbase64-hex-representation-projections · credential-in-nested-encoding-layers | Project policyT3 · Project policy | Left readable |
generic-literal-alphabet-edge-hex-mixed-in-envbase64-hex-representation-projections · credential-in-base64-or-hex-form | Project policyT3 · Project policy | Left readable |
generic-literal-alphabet-edge-hex-upper-in-envbase64-hex-representation-projections · credential-in-base64-or-hex-form | Project policyT3 · Project policy | Left readable |
generic-literal-alphabet-edge-hex-upper-in-jsonbase64-hex-representation-projections · credential-in-base64-or-hex-form | Project policyT3 · Project policy | Left readable |
generic-literal-padding-edge-base64-standard-padded-in-envbase64-hex-representation-projections · credential-in-base64-or-hex-form | Project policyT3 · Project policy | Left readable |
generic-literal-padding-edge-base64-standard-padded-in-jsonbase64-hex-representation-projections · credential-in-base64-or-hex-form | Project policyT3 · Project policy | Left readable |
generic-literal-padding-edge-base64-standard-padded-in-urlbase64-hex-representation-projections · credential-in-base64-or-hex-form | Project policyT3 · Project policy | Left readable |
generic-literal-padding-edge-base64-standard-padded-three-layers-in-envbase64-hex-representation-projections · credential-in-nested-encoding-layers | Project policyT3 · Project policy | Left readable |
generic-literal-padding-edge-base64-url-safe-unpadded-in-envbase64-hex-representation-projections · credential-in-base64-or-hex-form | Project policyT3 · Project policy | Left readable |
generic-literal-padding-edge-base64-url-safe-unpadded-in-jsonbase64-hex-representation-projections · credential-in-base64-or-hex-form | Project policyT3 · Project policy | Left readable |
generic-literal-padding-edge-base64-url-safe-unpadded-in-urlbase64-hex-representation-projections · credential-in-base64-or-hex-form | Project policyT3 · Project policy | Left readable |
generic-literal-padding-edge-base64-url-safe-unpadded-of-base64-standard-padded-in-envbase64-hex-representation-projections · credential-in-nested-encoding-layers | Project policyT3 · Project policy | Left readable |
generic-literal-padding-edge-base64-url-safe-unpadded-of-hex-upper-of-base64-standard-padded-in-jsonbase64-hex-representation-projections · credential-in-nested-encoding-layers | Project policyT3 · Project policy | Left readable |
generic-literal-padding-edge-hex-lower-in-envbase64-hex-representation-projections · credential-in-base64-or-hex-form | Project policyT3 · Project policy | Left readable |
generic-literal-padding-edge-hex-lower-in-urlbase64-hex-representation-projections · credential-in-base64-or-hex-form | Project policyT3 · Project policy | Left readable |
generic-literal-padding-edge-hex-lower-of-base64-standard-padded-in-envbase64-hex-representation-projections · credential-in-nested-encoding-layers | Project policyT3 · Project policy | Left readable |
generic-literal-padding-edge-hex-lower-of-hex-lower-in-envbase64-hex-representation-projections · credential-in-nested-encoding-layers | Project policyT3 · Project policy | Left readable |
generic-literal-padding-edge-hex-mixed-in-envbase64-hex-representation-projections · credential-in-base64-or-hex-form | Project policyT3 · Project policy | Left readable |
generic-literal-padding-edge-hex-upper-in-envbase64-hex-representation-projections · credential-in-base64-or-hex-form | Project policyT3 · Project policy | Left readable |
generic-literal-padding-edge-hex-upper-in-jsonbase64-hex-representation-projections · credential-in-base64-or-hex-form | Project policyT3 · Project policy | Left readable |
state-json-output-password-with-sensitive-truehashicorp-terraform-authored · terraform-json-sensitive-attribute-literal-beside-true-flag | Must redactT1 · Provider-documented | Left readable |
stdout-mask-where-source-has-environment-referencejupyter-notebook-files-authored · already-masked-values | Must not flagT3 · Project policy | Flagged |
generic-literal-alphabet-edge-basebase64-hex-representation-bases · literal-secrets-under-generic-credential-names | Project policyT3 · Project policy | Redacted |
generic-literal-padding-edge-basebase64-hex-representation-bases · literal-secrets-under-generic-credential-names | Project policyT3 · Project policy | Redacted |
api-keygeneric · literal-secrets-under-generic-credential-names | Project policyT3 · Project policy | Redacted |
arn-accountgeneric · secret-manager-grammar-imitations | Project policyT3 · Project policy | Redacted |
authgeneric · nested-yaml-literal-passwords | Project policyT3 · Project policy | Redacted |
aws-secret-access-key-truncated-near-missgeneric · credential-named-literal-near-miss | Project policyT3 · Project policy | Redacted |
block-literalgeneric · block-yaml-and-brace-prefixed-secret-literals | Project policyT3 · Project policy | Redacted |
browserbase-api-key-bb-test-key-near-missgeneric · credential-named-literal-near-miss | Project policyT3 · Project policy | Redacted |
cerebras-api-key-pinecone-hyphen-key-near-missgeneric · credential-named-literal-near-miss | Project policyT3 · Project policy | Redacted |
changed-secretgeneric · aws-example-keys-one-character-off | Project policyT3 · Project policy | Redacted |
client-secretgeneric · literal-secrets-under-generic-credential-names | Project policyT3 · Project policy | Redacted |
confluent-cloud-api-secret-legacy-overlong-value-near-missgeneric · credential-named-literal-near-miss | Project policyT3 · Project policy | Redacted |
databasegeneric · nested-yaml-literal-passwords | Project policyT3 · Project policy | Redacted |
datadog-api-key-short-keygeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
Sources
Documentation and code
- www.rfc-editor.org/rfc/rfc6749.txt
Research log
- redact-secret/redact-secret#653Research issue
- redact-secret/redact-secret#857Research issue
- redact-secret/redact-secret-benchmarks#365Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/8b6a5fde52ecb4dfce13f09c7a947062d21483c7/docs/audits/evidence/653/README.md